Langflow Langflow — CVE-2026-9205 (Critical)
Critical vendor advisory
CVE-2026-9205
Summary
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
Why it matters
This CVE carries a CRITICAL severity rating (CVSS 7.4) in Langflow Langflow. Patch or mitigate promptly. EPSS percentile: 11%.
Operator check
Review CVE-2026-9205 in your asset inventory. Apply patches per vendor guidance and verify Langflow is not exposed. CVSS score: 7.4. EPSS probability: 0.2%; percentile: 11%.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.